|
|
|
@@ -20,7 +20,7 @@ services:
|
|
|
|
- "--entrypoints.websecure.http.tls.certresolver=cloudflare"
|
|
|
|
- "--entrypoints.websecure.http.tls.certresolver=cloudflare"
|
|
|
|
- "--entrypoints.websecure.http.tls.domains[0].main=${DOMAIN_NAME}"
|
|
|
|
- "--entrypoints.websecure.http.tls.domains[0].main=${DOMAIN_NAME}"
|
|
|
|
- "--entrypoints.websecure.http.tls.domains[0].sans=*.${DOMAIN_NAME}"
|
|
|
|
- "--entrypoints.websecure.http.tls.domains[0].sans=*.${DOMAIN_NAME}"
|
|
|
|
- "--entrypoints.ssh.address=:${SSH_PORT}"
|
|
|
|
# - "--entrypoints.ssh.address=:${SSH_PORT}"
|
|
|
|
# Cloudflare IPs trusted for forwarded headers
|
|
|
|
# Cloudflare IPs trusted for forwarded headers
|
|
|
|
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
|
|
|
- "--entryPoints.web.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
|
|
|
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
|
|
|
- "--entryPoints.websecure.forwardedHeaders.trustedIPs=173.245.48.0/20,103.21.244.0/22,103.22.200.0/22,103.31.4.0/22,141.101.64.0/18,108.162.192.0/18,190.93.240.0/20,188.114.96.0/20,197.234.240.0/22,198.41.128.0/17,162.158.0.0/15,104.16.0.0/13,104.24.0.0/14,172.64.0.0/13,131.0.72.0/22"
|
|
|
|
@@ -52,7 +52,7 @@ services:
|
|
|
|
env_file:
|
|
|
|
env_file:
|
|
|
|
- .env
|
|
|
|
- .env
|
|
|
|
secrets:
|
|
|
|
secrets:
|
|
|
|
- SSH_PORT
|
|
|
|
# - SSH_PORT
|
|
|
|
- CF_API_KEY
|
|
|
|
- CF_API_KEY
|
|
|
|
- CF_API_EMAIL
|
|
|
|
- CF_API_EMAIL
|
|
|
|
volumes:
|
|
|
|
volumes:
|
|
|
|
@@ -61,15 +61,14 @@ services:
|
|
|
|
ports:
|
|
|
|
ports:
|
|
|
|
- "80:80"
|
|
|
|
- "80:80"
|
|
|
|
- "443:443"
|
|
|
|
- "443:443"
|
|
|
|
- "558:558"
|
|
|
|
|
|
|
|
networks:
|
|
|
|
networks:
|
|
|
|
- frontend
|
|
|
|
- frontend
|
|
|
|
- webapp
|
|
|
|
- webapp
|
|
|
|
- mgmt
|
|
|
|
- mgmt
|
|
|
|
- remote
|
|
|
|
- remote
|
|
|
|
secrets:
|
|
|
|
secrets:
|
|
|
|
SSH_PORT:
|
|
|
|
# SSH_PORT:
|
|
|
|
file: .secrets/SSH_PORT
|
|
|
|
# file: .secrets/SSH_PORT
|
|
|
|
CF_API_KEY:
|
|
|
|
CF_API_KEY:
|
|
|
|
file: .secrets/CF_API_KEY
|
|
|
|
file: .secrets/CF_API_KEY
|
|
|
|
CF_API_EMAIL:
|
|
|
|
CF_API_EMAIL:
|
|
|
|
|